-
Notifications
You must be signed in to change notification settings - Fork 2.9k
Added new samples for CMEK and Annotations #10223
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
dhavalbhensdadiya-crest
wants to merge
5
commits into
GoogleCloudPlatform:main
Choose a base branch
from
dhavalbhensdadiya-crest:feature/cmek-annotations
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from 2 commits
Commits
Show all changes
5 commits
Select commit
Hold shift + click to select a range
e337c21
Adding code samples for creating secret with customer managed encrypt…
dhavalbhensdadiya-crest 36203bb
Improved readme and created new secret specific for deleting annotations
dhavalbhensdadiya-crest 0acae16
Applied suggestions from code review
dhavalbhensdadiya-crest 9d6e4ee
Added args to main function
dhavalbhensdadiya-crest 710bb85
Moved KMS key validation check to BeforeClass setup
dhavalbhensdadiya-crest File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
76 changes: 76 additions & 0 deletions
76
secretmanager/src/main/java/secretmanager/CreateSecretWithCmek.java
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,76 @@ | ||
| /* | ||
| * Copyright 2026 Google LLC | ||
| * | ||
| * Licensed under the Apache License, Version 2.0 (the "License"); | ||
| * you may not use this file except in compliance with the License. | ||
| * You may obtain a copy of the License at | ||
| * | ||
| * http://www.apache.org/licenses/LICENSE-2.0 | ||
| * | ||
| * Unless required by applicable law or agreed to in writing, software | ||
| * distributed under the License is distributed on an "AS IS" BASIS, | ||
| * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
| * See the License for the specific language governing permissions and | ||
| * limitations under the License. | ||
| */ | ||
|
|
||
| package secretmanager; | ||
|
|
||
| // [START secretmanager_create_secret_with_annotations] | ||
| import com.google.cloud.secretmanager.v1.CustomerManagedEncryption; | ||
| import com.google.cloud.secretmanager.v1.ProjectName; | ||
| import com.google.cloud.secretmanager.v1.Replication; | ||
| import com.google.cloud.secretmanager.v1.Secret; | ||
| import com.google.cloud.secretmanager.v1.SecretManagerServiceClient; | ||
| import java.io.IOException; | ||
|
|
||
| public class CreateSecretWithCmek { | ||
|
|
||
| public static void main() throws IOException { | ||
| // TODO(developer): Replace these variables before running the sample. | ||
|
|
||
| // This is the id of the GCP project | ||
| String projectId = "your-project-id"; | ||
| // This is the id of the secret to act on | ||
| String secretId = "your-secret-id"; | ||
| // This is the Full kms key name to be used for Cmek. | ||
| String kmsKeyName = "your-kms-key-name"; | ||
| createSecretWithCmek(projectId, secretId, kmsKeyName); | ||
| } | ||
|
|
||
| // Create a secret with annotations. | ||
|
dhavalbhensdadiya-crest marked this conversation as resolved.
Outdated
|
||
| public static Secret createSecretWithCmek(String projectId, String secretId, String kmsKeyName) | ||
| throws IOException { | ||
|
|
||
| // Initialize client that will be used to send requests. This client only needs | ||
| // to be created | ||
| // once, and can be reused for multiple requests. | ||
| try (SecretManagerServiceClient client = SecretManagerServiceClient.create()) { | ||
|
|
||
| // Build the secret name. | ||
| ProjectName projectName = ProjectName.of(projectId); | ||
|
|
||
| // Build the Cmek configuration. | ||
| CustomerManagedEncryption customerManagedEncryption = | ||
| CustomerManagedEncryption.newBuilder().setKmsKeyName(kmsKeyName).build(); | ||
|
|
||
| // Build the replication using Cmek. | ||
| Replication secretReplication = | ||
| Replication.newBuilder() | ||
| .setAutomatic( | ||
| Replication.Automatic.newBuilder() | ||
| .setCustomerManagedEncryption(customerManagedEncryption) | ||
| .build()) | ||
| .build(); | ||
|
|
||
| // Build the secret to create with labels. | ||
|
dhavalbhensdadiya-crest marked this conversation as resolved.
Outdated
|
||
| Secret secret = Secret.newBuilder().setReplication(secretReplication).build(); | ||
|
|
||
| // Create the secret. | ||
| Secret createdSecret = client.createSecret(projectName, secretId, secret); | ||
| System.out.printf("Created secret %s\n", createdSecret.getName()); | ||
| return createdSecret; | ||
| } | ||
| } | ||
| } | ||
| // [END secretmanager_create_secret_with_annotations] | ||
|
dhavalbhensdadiya-crest marked this conversation as resolved.
Outdated
|
||
77 changes: 77 additions & 0 deletions
77
secretmanager/src/main/java/secretmanager/DeleteSecretAnnotations.java
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,77 @@ | ||
| /* | ||
| * Copyright 2026 Google LLC | ||
| * | ||
| * Licensed under the Apache License, Version 2.0 (the "License"); | ||
| * you may not use this file except in compliance with the License. | ||
| * You may obtain a copy of the License at | ||
| * | ||
| * http://www.apache.org/licenses/LICENSE-2.0 | ||
| * | ||
| * Unless required by applicable law or agreed to in writing, software | ||
| * distributed under the License is distributed on an "AS IS" BASIS, | ||
| * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
| * See the License for the specific language governing permissions and | ||
| * limitations under the License. | ||
| */ | ||
|
|
||
| package secretmanager; | ||
|
|
||
| // [START secretmanager_delete_secret_annotations] | ||
| import com.google.cloud.secretmanager.v1.Secret; | ||
| import com.google.cloud.secretmanager.v1.SecretManagerServiceClient; | ||
| import com.google.cloud.secretmanager.v1.SecretName; | ||
| import com.google.protobuf.FieldMask; | ||
| import com.google.protobuf.util.FieldMaskUtil; | ||
| import java.io.IOException; | ||
| import java.util.HashMap; | ||
| import java.util.Map; | ||
|
|
||
| public class DeleteSecretAnnotations { | ||
|
|
||
| public static void main() throws IOException { | ||
| // TODO(developer): Replace these variables before running the sample. | ||
|
|
||
| // This is the id of the GCP project | ||
| String projectId = "your-project-id"; | ||
| // This is the id of the secret to act on | ||
| String secretId = "your-secret-id"; | ||
| deleteSecretAnnotations(projectId, secretId); | ||
| } | ||
|
|
||
| // Delete annotations from an existing secret. | ||
| public static Secret deleteSecretAnnotations(String projectId, String secretId) | ||
| throws IOException { | ||
| // Initialize client that will be used to send requests. This client only needs | ||
| // to be created | ||
| // once, and can be reused for multiple requests. | ||
| try (SecretManagerServiceClient client = SecretManagerServiceClient.create()) { | ||
| // Build the name of the secret. | ||
| SecretName secretName = SecretName.of(projectId, secretId); | ||
|
|
||
| // Get the current secret | ||
| Secret existingSecret = client.getSecret(secretName); | ||
|
|
||
| // Remove all annotations | ||
| Map<String, String> existingAnnotationsMap = | ||
| new HashMap<String, String>(existingSecret.getAnnotationsMap()); | ||
| existingAnnotationsMap.clear(); | ||
|
|
||
| // Build the updated secret. | ||
| Secret secret = | ||
| Secret.newBuilder() | ||
| .setName(secretName.toString()) | ||
| .putAllAnnotations(existingAnnotationsMap) | ||
| .build(); | ||
|
dhavalbhensdadiya-crest marked this conversation as resolved.
Outdated
|
||
|
|
||
| // Create the field mask for updating only the annotations | ||
| FieldMask fieldMask = FieldMaskUtil.fromString("annotations"); | ||
|
|
||
| // Update the secret. | ||
| Secret updatedSecret = client.updateSecret(secret, fieldMask); | ||
| System.out.printf("Deleted annotations from %s\n", updatedSecret.getName()); | ||
|
|
||
| return updatedSecret; | ||
| } | ||
| } | ||
| } | ||
| // [END secretmanager_delete_secret_annotations] | ||
75 changes: 75 additions & 0 deletions
75
secretmanager/src/main/java/secretmanager/regionalsamples/CreateRegionalSecretWithCmek.java
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,75 @@ | ||
| /* | ||
| * Copyright 2026 Google LLC | ||
| * | ||
| * Licensed under the Apache License, Version 2.0 (the "License"); | ||
| * you may not use this file except in compliance with the License. | ||
| * You may obtain a copy of the License at | ||
| * | ||
| * http://www.apache.org/licenses/LICENSE-2.0 | ||
| * | ||
| * Unless required by applicable law or agreed to in writing, software | ||
| * distributed under the License is distributed on an "AS IS" BASIS, | ||
| * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
| * See the License for the specific language governing permissions and | ||
| * limitations under the License. | ||
| */ | ||
|
|
||
| package secretmanager.regionalsamples; | ||
|
|
||
| // [START secretmanager_create_regional_secret_with_cmek] | ||
| import com.google.cloud.secretmanager.v1.CustomerManagedEncryption; | ||
| import com.google.cloud.secretmanager.v1.LocationName; | ||
| import com.google.cloud.secretmanager.v1.Secret; | ||
| import com.google.cloud.secretmanager.v1.SecretManagerServiceClient; | ||
| import com.google.cloud.secretmanager.v1.SecretManagerServiceSettings; | ||
| import java.io.IOException; | ||
|
|
||
| public class CreateRegionalSecretWithCmek { | ||
|
|
||
| public static void main() throws IOException { | ||
| // TODO(developer): Replace these variables before running the sample. | ||
|
|
||
| // This is the id of the GCP project | ||
| String projectId = "your-project-id"; | ||
| // Location of the secret. | ||
| String locationId = "your-location-id"; | ||
| // This is the id of the secret to act on | ||
| String secretId = "your-secret-id"; | ||
| // This is the Full kms key name to be used for Cmek. | ||
| String kmsKeyName = "your-kms-key-name"; | ||
| createRegionalSecretWithCmek(projectId, locationId, secretId, kmsKeyName); | ||
| } | ||
|
|
||
| // Create a new regional secret with customer-managed encryption key. | ||
| public static Secret createRegionalSecretWithCmek( | ||
| String projectId, String locationId, String secretId, String kmsKeyName) throws IOException { | ||
|
|
||
| // Endpoint to call the regional secret manager server | ||
| String apiEndpoint = String.format("secretmanager.%s.rep.googleapis.com:443", locationId); | ||
| SecretManagerServiceSettings secretManagerServiceSettings = | ||
| SecretManagerServiceSettings.newBuilder().setEndpoint(apiEndpoint).build(); | ||
|
|
||
| // Initialize client that will be used to send requests. This client only needs | ||
| // to be created | ||
| // once, and can be reused for multiple requests. | ||
| try (SecretManagerServiceClient client = | ||
| SecretManagerServiceClient.create(secretManagerServiceSettings)) { | ||
| // Build the parent name from the project and location. | ||
| LocationName locationName = LocationName.of(projectId, locationId); | ||
|
|
||
| // Build the customer-managed encryption configuration. | ||
| CustomerManagedEncryption customerManagedEncryption = | ||
| CustomerManagedEncryption.newBuilder().setKmsKeyName(kmsKeyName).build(); | ||
|
|
||
| // Build the secret with customer-managed encryption key. | ||
| Secret secret = | ||
| Secret.newBuilder().setCustomerManagedEncryption(customerManagedEncryption).build(); | ||
|
|
||
| // Create the secret. | ||
| Secret createdSecret = client.createSecret(locationName.toString(), secretId, secret); | ||
| System.out.printf("Created secret %s\n", createdSecret.getName()); | ||
| return createdSecret; | ||
| } | ||
| } | ||
| } | ||
| // [END secretmanager_create_regional_secret_with_cmek] |
88 changes: 88 additions & 0 deletions
88
...tmanager/src/main/java/secretmanager/regionalsamples/DeleteRegionalSecretAnnotations.java
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,88 @@ | ||
| /* | ||
| * Copyright 2026 Google LLC | ||
| * | ||
| * Licensed under the Apache License, Version 2.0 (the "License"); | ||
| * you may not use this file except in compliance with the License. | ||
| * You may obtain a copy of the License at | ||
| * | ||
| * http://www.apache.org/licenses/LICENSE-2.0 | ||
| * | ||
| * Unless required by applicable law or agreed to in writing, software | ||
| * distributed under the License is distributed on an "AS IS" BASIS, | ||
| * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
| * See the License for the specific language governing permissions and | ||
| * limitations under the License. | ||
| */ | ||
|
|
||
| package secretmanager.regionalsamples; | ||
|
|
||
| // [START secretmanager_delete_regional_secret_annotations] | ||
| import com.google.cloud.secretmanager.v1.Secret; | ||
| import com.google.cloud.secretmanager.v1.SecretManagerServiceClient; | ||
| import com.google.cloud.secretmanager.v1.SecretManagerServiceSettings; | ||
| import com.google.cloud.secretmanager.v1.SecretName; | ||
| import com.google.protobuf.FieldMask; | ||
| import com.google.protobuf.util.FieldMaskUtil; | ||
| import java.io.IOException; | ||
| import java.util.HashMap; | ||
| import java.util.Map; | ||
|
|
||
| public class DeleteRegionalSecretAnnotations { | ||
|
|
||
| public static void main() throws IOException { | ||
| // TODO(developer): Replace these variables before running the sample. | ||
|
|
||
| // This is the id of the GCP project | ||
| String projectId = "your-project-id"; | ||
| // Location of the secret. | ||
| String locationId = "your-location-id"; | ||
| // This is the id of the secret to act on | ||
| String secretId = "your-secret-id"; | ||
| deleteRegionalSecretAnnotations(projectId, locationId, secretId); | ||
| } | ||
|
|
||
| // Delete annotations from an existing regional secret. | ||
| public static Secret deleteRegionalSecretAnnotations( | ||
| String projectId, String locationId, String secretId) throws IOException { | ||
|
|
||
| // Endpoint to call the regional secret manager server | ||
| String apiEndpoint = String.format("secretmanager.%s.rep.googleapis.com:443", locationId); | ||
| SecretManagerServiceSettings secretManagerServiceSettings = | ||
| SecretManagerServiceSettings.newBuilder().setEndpoint(apiEndpoint).build(); | ||
|
|
||
| // Initialize client that will be used to send requests. This client only needs | ||
| // to be created | ||
| // once, and can be reused for multiple requests. | ||
| try (SecretManagerServiceClient client = | ||
| SecretManagerServiceClient.create(secretManagerServiceSettings)) { | ||
| // Build the name of the secret. | ||
| SecretName secretName = | ||
| SecretName.ofProjectLocationSecretName(projectId, locationId, secretId); | ||
|
|
||
| // Get the current secret | ||
| Secret existingSecret = client.getSecret(secretName); | ||
|
|
||
| // Remove all annotations | ||
| Map<String, String> existingAnnotationsMap = | ||
| new HashMap<String, String>(existingSecret.getAnnotationsMap()); | ||
| existingAnnotationsMap.clear(); | ||
|
|
||
| // Build the updated secret. | ||
| Secret secret = | ||
| Secret.newBuilder() | ||
| .setName(secretName.toString()) | ||
| .putAllAnnotations(existingAnnotationsMap) | ||
| .build(); | ||
|
dhavalbhensdadiya-crest marked this conversation as resolved.
Outdated
|
||
|
|
||
| // Create the field mask for updating only the annotations | ||
| FieldMask fieldMask = FieldMaskUtil.fromString("annotations"); | ||
|
|
||
| // Update the secret. | ||
| Secret updatedSecret = client.updateSecret(secret, fieldMask); | ||
| System.out.printf("Deleted annotations from %s\n", updatedSecret.getName()); | ||
|
|
||
| return updatedSecret; | ||
| } | ||
| } | ||
| } | ||
| // [END secretmanager_delete_regional_secret_annotations] | ||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.